Consent Log
A consent log is a record of the choices users make when they interact with a cookie consent banner or similar mechanism, such as agreeing to or refusing the use of their data. It typically captures information that lets an organization look up a particular user's decision later. Consent logs are commonly generated and stored by consent management tools built into websites.
A consent log is a stored record of consent (and, where applicable, refusal or withdrawal) captured through a consent mechanism such as a cookie banner or preference center. In practice, consent management platforms and website plugins log each interaction along with metadata intended to enable later lookup of a user's specific choices; the exact fields captured vary by tool and configuration. Consent logging is generally understood to support the accountability and demonstrability expectations associated with consent under EU frameworks, but the precise records, retention periods, and evidentiary standards required depend on the applicable legal regime and regulator guidance, which this definition does not resolve. Maintaining a consent log is a technical and organizational measure that supports compliance but does not by itself guarantee that consent was validly obtained.
Why it matters
Under EU frameworks such as the GDPR, controllers are generally expected to be able to demonstrate that they obtained valid consent where consent is the basis for processing personal data. A consent log supports this accountability expectation by preserving a record of the choices users made when interacting with a cookie banner or preference center, so that an organization can later look up a particular user's decision. Without such a record, an organization may struggle to show whether, when, and to what a user agreed or objected.
It is important not to overstate what a consent log achieves. Maintaining a log is a technical and organizational measure that supports compliance, but it does not by itself guarantee that consent was validly obtained. If the underlying consent mechanism was flawed, for example, if it relied on pre-ticked boxes, implied consent, or a design that did not meet the freely given, specific, informed, and unambiguous standard applied in most EU jurisdictions, a log will simply record an interaction that may not amount to valid consent.
The precise records, retention periods, and evidentiary standards that regulators expect vary by legal regime and by data protection authority guidance, and these questions are not resolved by the mere existence of a log. Requirements also differ outside the EU: frameworks such as certain US state privacy laws often rely on opt-out mechanisms rather than opt-in consent, which affects what a record needs to capture. Organizations should therefore treat consent logging as one part of a broader compliance approach rather than a standalone solution.
Who it's relevant to
Inside Consent Log
Common questions
Answers to the questions practitioners most commonly ask about Consent Log.
